projectsend vulnerabilities
CVEs whose affected-version data names the projectsend package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2024-11680Critical· 9.8CISA KEVPoCProjectSend versions prior to r1720 are affected by an improper authentication vulnerability
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of …
▾ Hadalprojectsend · projectsendEPSS 92%via NVD
CVE-2020-28874High· 7.5PoCreset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).
▾ Midnightprojectsend · projectsendEPSS 2.4%via NVD